Problem Statement
Which mistake can lead to an OAuth or OIDC login bypass?
Explanation
If the client trusts any token that decodes, an attacker can use a token from a different app or a different identity provider. Always check issuer, audience, expiration, and the nonce for implicit and hybrid flows.
Code Solution
SolutionRead Only
verify(id_token, { issuer, audience, nonce, exp })